Назад
Company hidden
10 дней назад

Senior Product Security Engineer (SaaS Security)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Taiwan
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Product Security Engineer (SaaS Security): Strengthening SaaS products, software supply chains, development pipelines, and cloud infrastructure with an accent on vulnerability management, secure architecture, and automated security controls. Focus on designing security features, improving CVE remediation and patch reliability, and building scalable protections across applications, APIs, containers, and cloud platforms.

Location: Taipei, Taiwan

Company

hirify.global Security provides a SaaS security platform that protects enterprise applications, integrations, software supply chains, and cloud environments.

What you will do

  • Perform security architecture, design, threat-modeling, code, and infrastructure reviews across products, services, APIs, data pipelines, and cloud components.
  • Lead end-to-end CVE and vulnerability management, including exposure analysis, risk assessment, prioritization, remediation, testing, deployment, and validation.
  • Improve patch reliability through regression testing, staged rollouts, compatibility validation, rollback mechanisms, and production monitoring.
  • Strengthen CI/CD and software supply chain security with dependency, static, container, infrastructure-as-code, and secrets scanning.
  • Build security features, reusable libraries, automation, policies, developer tools, and controls for backend services, APIs, and cloud infrastructure.
  • Investigate security incidents, define security standards and release criteria, improve risk visibility, and mentor engineers across product and infrastructure teams.

Requirements

  • Significant experience in product security, application security, security engineering, cloud security, or a related discipline.
  • Strong knowledge of secure software development, application security risks, authentication, authorization, injection, secrets exposure, and data leakage.
  • Hands-on software engineering experience with Python, Go, Java, Kotlin, TypeScript, or a comparable language.
  • Experience securing cloud-native SaaS products, distributed systems, APIs, microservices, data-processing platforms, containers, and Kubernetes.
  • Experience implementing CI/CD security controls, managing CVEs, conducting architecture reviews, threat modeling, secure code reviews, and security testing.
  • Strong written and verbal English communication skills are required.

Nice to have

  • Experience with cybersecurity, identity security, SaaS security, or enterprise security products.
  • Knowledge of software supply chain security, SBOMs, artifact signing, provenance, dependency governance, policy-as-code, or automated remediation.
  • Familiarity with OWASP, CWE, CVSS, EPSS, NIST SSDF, or SLSA.
  • Experience with penetration testing, vulnerability research, incident response, multi-tenant SaaS security, or data privacy.
  • Mandarin proficiency.

Culture & Benefits

  • Collaborate with Product Engineering, Platform Engineering, SRE, Security Research, and Infrastructure teams across Taiwan, the US, the UK, and Australia.
  • Work across the full product lifecycle, from architecture and implementation through deployment and production operations.
  • Contribute to a security-focused engineering environment where recurring security work is automated and integrated into everyday development.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →